Malware

About “Win32/Filecoder.EZ” infection

Malware Removal

The Win32/Filecoder.EZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.EZ virus can do?

  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Filecoder.EZ?


File Info:

crc32: 24E2C058
md5: dca33a7dd1214466291fbeb6cfda60d0
name: DCA33A7DD1214466291FBEB6CFDA60D0.mlw
sha1: 95ddf5a97d1d3da24f0faaa8b6b2e8bdd45ae0ca
sha256: 54efb6ce11d8dbffd648e710d4953c0d5660849444c81315841ec8c571e7cc33
sha512: b7ba8cc355fccd096fea11bc3aabd9601c084175317e8ccc3428afddffd4b00defa3f4c11e5d666491a2afca5e2e0a76d33ed295291666c6716ea945f930508f
ssdeep: 3072:+bSx4WP79r1gI7kryktQpwMbM+w2AqVLCfTDzr:+bSfJqGp++wI27
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Win32/Filecoder.EZ also known as:

K7AntiVirusTrojan ( 0055e3ef1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
CylanceUnsafe
ZillyaTrojan.Deshacop.Win32.307
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Sarento.a88cc2f6
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.97d1d3
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.EZ
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Deshacop.dwuzjw
TencentWin32.Trojan.Raas.Auto
SophosMal/Generic-S
ComodoTrojWare.Win32.Ransom.Sarento.A@5xb8st
BitDefenderThetaGen:NN.ZexaF.34688.iGW@aitboTp
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Worm.ch
FireEyeGeneric.mg.dca33a7dd1214466
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Deshacop.hc
AviraHEUR/AGEN.1126426
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.142B8CC
KingsoftWin32.Troj.Deshacop.a.(kcloud)
MicrosoftRansom:Win32/Sarento.B
AegisLabTrojan.Win32.Deshacop.4!c
AhnLab-V3Malware/Win32.Generic.C1066403
McAfeeArtemis!DCA33A7DD121
MAXmalware (ai score=99)
VBA32Trojan.Deshacop
MalwarebytesMalware.AI.3940371145
PandaGeneric Suspicious
RisingRansom.Sarento!8.2BEC (CLOUD)
YandexTrojan.GenAsa!REwiooJRq+Q
IkarusTrojan-Ransom.Sarento
FortinetW32/Deshacop.AGF!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Win32/Filecoder.EZ?

Win32/Filecoder.EZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment